Description
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.


This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack. This issue was fixed in version 3.0.30
Title Denial of Service in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-770
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:28.116Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82936

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:06.608Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:24.150

Modified: 2026-09-28T16:31:16.073

Link: CVE-2026-82936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:15:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling